Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationidentity-authentication-vulnerabilityinternet-facing-service-vulnerability

SmarterMail WT-2026-0001 Authentication Bypass Enables Admin Takeover and RCE

Updated 3mo agoFirst seen Jan 22, 20266 sources

SmarterTools SmarterMail patched a critical authentication bypass tracked as WT-2026-0001 after researchers reported that attackers can reset the system administrator password without authentication by abusing the /api/v1/auth/force-reset-password endpoint. The flaw stems from logic in SmarterMail.Web.Api.AuthenticationController.ForceResetPassword that permits anonymous access and trusts a user-supplied boolean (IsSysAdmin); when set to true, the code path updates an admin account’s password without validating the old password or enforcing authorization checks.

Both reporting indicate the issue is actively exploited in the wild, with observed exploitation occurring within days of the vendor patch (including reports of activity as soon as two days after release). Once an attacker resets the admin password, they can take over the mail server and leverage built-in administrative capabilities to execute OS commands, effectively achieving remote code execution (RCE) and full compromise of affected SmarterMail deployments; the patch was released as Build 9511 following responsible disclosure by watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah.

Share:
SmarterMail WT-2026-0001 Authentication Bypass Enables Admin Takeover and RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 22, 20265mo ago

CVE-2026-23760 is assigned to the SmarterMail vulnerability

The SmarterMail authentication bypass was assigned CVE-2026-23760, covering versions prior to Build 9511. The CVE record was received on 2026-01-22 and documented the issue as an authentication bypass in the password reset API leading to full administrative compromise.

watchTowr publicly discloses WT-2026-0001 and exploitation details

On 2026-01-22, watchTowr Labs publicly disclosed the SmarterMail flaw, describing how unauthenticated attackers could set IsSysAdmin=true, reset an admin password, and then abuse features such as Volume Mounts to achieve SYSTEM-level remote code execution. The disclosure also included evidence of active exploitation and a proof-of-concept path to shell access.

Jan 17, 20265mo ago

Forum report indicates admin password was changed via the vulnerable endpoint

A SmarterMail forum post dated 2026-01-17 suggested the vulnerable endpoint had been used to change an administrator password in the wild. This became an early public indicator of active exploitation.

Attackers begin exploiting the flaw after patch release

Evidence from logs and later reporting indicates attackers started exploiting unpatched SmarterMail systems within about 48 hours of the patch, likely by reverse engineering Build 9511. The activity involved resetting administrator passwords through the force-reset-password endpoint.

Jan 15, 20265mo ago

SmarterTools releases SmarterMail Build 9511 patch

SmarterTools released SmarterMail Build 9511 to fix the password-reset API issue by adding old-password validation for administrator resets. Release notes reportedly described the update only as containing critical security fixes.

Jan 8, 20266mo ago

watchTowr reports SmarterMail auth bypass to SmarterTools

watchTowr Labs reported a critical SmarterMail authentication-bypass flaw, later tracked as WT-2026-0001, to the vendor. BleepingComputer says the report was made on 2026-01-08.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
1 linked
Smartermail
Organizations
3 linked
SmartertoolsWatchTowrThe Hacker News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.